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THE MAILING DATE OF THIS COMMUNICATION. 

- Extensions of time may be available under the provisions of 37 CFR 1.136(a). In no event, however, may a reply be timely filed 
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- Failure to reply within the set or extended period for reply will, by statute, cause the application to become ABANDONED (35 U.S.C. § 1 33). 
Any reply received by the Office later than three months after the mailing date of this communication, even if timely filed, may reduce any 
earned patent term adjustment. See 37 CFR 1.704(b). 
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2a)n This action is FINAL. 2b)S This action is non-final. 

3) D Since this application is in condition for allowance except for formal matters, prosecution as to the merits is 

closed in accordance with the practice under Ex parte Quayle, 1935 CD. 11, 453 O.G. 213. 

Disposition of Claims 
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10) 0 The drawing(s) filed on is/are: a)n accepted or b)n objected to by the Examiner. 

Applicant may not request that any objection to the drawing(s) be held in abeyance. See 37 CFR 1 .85(a). 
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application from the International Bureau (PCT Rule 17.2(a)). 
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DETAILED ACTION 



1 . Claim 1 -6 are presented for examination. 

Specification 

2. The abstract of the disclosure is objected to because: 

The form and legal phraseology often used in patent claims, such as "means" 
and "said," should be avoided. 

Correction is required. See MPEP § 608.01(b). 



3. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 

obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed 
or described as set forth in section 102 of this title, if the differences between the 
subject matter sought to be patented and the prior art are such that the subject 
matter as a whole would have been obvious at the time the invention was made 
to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was 
made. 



4. Claims 1, 3-4, and 6 are rejected under 35 U.S.C. 103(a) as being unpatentable 
over Ichihara (U.S. Patent 6,496,937) in view of Dunn (U.S. Patent 6701439). 



Claim Rejections - 35 USC § 103 
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5. As per claim 1, Icliihara teaches a method for which a database at least 
comprises one table with at least one user password, which password is used for 
logging on to said database, wherein said password is stored as a hash value, said 
method comprising the steps of: 

adding a trigger (date and time) to said table, said trigger at least triggering an 
action (generating password) through a database (Col. 6 lines 15-45, and Figures 3,6); 

calculating a new password hash value differing from said stored password hash 
value when said trigger is triggered (col. 2 lines 33-41, col. 3 lines 55-66, col. 6 lines 15- 
45, and Fig. 3); 

replacing said stored password hash value with said new password hash value. 
(Col. 4 lines 14-21, and col. 8 line 49-53); 

Ichihara fails to teach preventing an administrator to impersonate a user of a 
relational database and triggering when an administrator alters said table through a 
database management system (DBMS). 

However, Dunn teaches fraud detection and nuisance reporting features to 
impede discourage and surveil unauthorized users, and rejecting message is returned 
when a hacker tries to break in to a system. (Col. 5 lines 56-67; col. 6 lines 23-45); 

It would have been obvious to one having ordinary skill in the art at the time the 
invention was made to combine the teachings of Ichihara and Dunn to prevent an 
administrator to impersonate a user of a relational database and triggering when an 
administrator alters said table through a database management system (DBMS) 
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because it would provides for identification and surveillance of suspected hackers so 
that appropriate action will be taken against them. 

6. As per claim 3, Ichihara and Dunn disclose comparing for each active user 
having access to sensitive data, the hash value of the current login password with the 
hash value of the currently stored password (Ichihara, col. 5 line 56 - col. 6 line 52; 
Dunn, col. 3 lines 21-37; col. 6 lines 23-45). 

7. As per claim 4, Ichihara and Dunn teach comparing is performed after every 
change of the database content by the user (Ichihara, col. 5 line 56 - coL 6 line 52; 
Dunn, col. 3 lines 21-37; col. 6 lines 23-45). 

8. As to claim 6, it has similar limitations as claim 1 ; therefore, it is being rejected 
under the same rationale. 

9. Claim 2 is rejected under 35 U.S.C. 103(a) as being unpatentable over Ichihara 
(U.S. Patent 6,496,937), Dunn (U.S. Patent 6701439), and further in view of Leighton et 
al. (Leighton, Patent No. 4,995,081). 

10. As per claim 2, Ichihara teaches comparing said trigger control value at the 
startup and at regular intervals with a recalculated check value. (Col. 6 lines 16-28; 
monitor when predetermined number of elapsed dates and time measured by the timer); 
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Ichihara and Dunn teach the invention as discussed above. However, Ichihara 
and Dunn do not explicitly teach calculating a check value of said trigger such as a hash 
value. 

Leighton teaches that hash function that being used to calculate a value is well- 
known (col. 5 line 57- col. 6 linelO). 

Therefore it would have been obvious to one having ordinary skill in the art at the 
time the invention was made to combine the teachings of Ichihara, Dunn, and Leighton 
to use hash function to calculate a check value of said trigger because it would prevent 
unauthorized use during transaction processing. 

11. Claim 5 is rejected under 35 U.S.C. 103(a) as being unpatentable over Ichihara 
(U.S. Patent 6,496,937), in view of Dunn (U.S. Patent 6701439), and further in view of 
Geary (U.S. Patent 6,070,160). 

12. As per claim 5, Ichihara and Dunn teach the invention as discussed above. 
However, Ichihara and Dunn do not explicitly teach means for reading a log of actions 
on said database, means for identifying commands for altering user passwords in said 
log and means for identifying which user passwords that have been changed. 

Geary teaches security routine that provides passwords, change passwords, 
control deletions from the system, perform audits, add and delete users, review logs 
(Col. 14 lines 1-11, and Figs. 2 and 4). 
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It would have been obvious to one having ordinary skill in the art at the time the 
invention was made to combine the teachings of Ichihara, Dunn, and Geary to read a 
log of actions on said database, to identify commands for altering user passwords in 
said log and which user passwords that have been changed because it would enhance 
overall computer security. 

13. Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Eleni A Shiferaw whose telephone number is 
7033050326. The examiner can normally be reached on Mon-Fri 8:00am-5:00pm. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Ayaz R Sheikh can be reached on 7033059648. The fax phone number for 
the organization where this application or proceeding is assigned is 703-872-9306. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). 
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